4 ms·
Very interesting article. It mainly focuses on what happens after an attack, but I was left wondering - before selling the insurance, does the insurance company
by impostervt 5y ago
Very interesting article. It mainly focuses on what happens after an attack, but I was left wondering - before selling the insurance, does the insurance company require the insured to perform any kind of basic cyber security audit? Are they required to take regular backups, and to test those backups on a regular basis?
I know I can't insure my home if it doesn't meet basic fire-proofing standards. Does cyber security insurance work the same way?
- IG_Semmelweiss 5y agoNo. However there will be written requirements into the policy on security expectations. When the incident happens, there will be a post mortem review of whether the security best practices were implemented and how they contributed or hindered to the incident The insurer will use that to either deny some coverage, increase premiums or worst case, advice that the policy will not be renewed. The way requirements are handled is true for small or medium clients. I dont have experience with large firms but i would not expect those clients to be different. (One does not go about winning business by asking new clients to submit to an audit prior to switching) That being said, there may be audit requirements at renewals.
- jon-wood 5y agoAs with most things in computer security this is mostly performed as a self-assessment. The insurer will provide a set of questions about things like backup policies, access control, and encryption which you’re expected to answer. Unless it’s a ridiculously valuable policy they’re not going to get pentesters in to verify your answers, in the same way your home insurer doesn’t send someone round to check you really do have smoke detectors and locks on your front door.
- mox1 5y agoIt's a "self-assessment" until it comes time to pay the insurance. Then the insurance co pulls out that old file and checks it :)
- dd82 5y agoDepends on the company. Mine (Coalition) does do scanning and ensuring basic metrics and protection are in place. For example, RDP ports must be closed, which is an auto-decline. The client is given an output of our findings and what would be necessary for us to underwrite the policy. Any cyber insurance company that does not do this is exposing themselves to outsized risk because they're writing policies based on incomplete data on their exposure.
- motohagiography 5y agoNaive and perhaps pedantic question from me, does using scanning for monitoring not create an aggregated/correlated re-insurance risk? It could seem like the PCI/NIST and others are akin to a building's electrical or fire code, which raises all boats, but it also concentrates overall portfolio risk in high-value assets with catastrophic failures. Like saying, "we only insure unsinkable ships certified by Titanic & Co., it's free money." Where instead of Titanic, with cyber the risk is only diversified over configurations of MSFT, AMZN, GOOG products and some linux kernels. Not a criticism, but as a security architect, it's the most interesting set of questions of all. The insurance incentive to close ports is great, and super positive, perhaps how that risk gets managed on the back end is secret sauce.
- balgan 5y agoThere are multiple parts to the underwriting process (full disclosure I run the team that does data collection and security at Coalition where the op you're replying to works). Part of the data we collect is used for risk selection (do we want you on our book?) and then other piece is used for pricing and thats where technologies, providers and a lot of other things come in! Lmk if u have any questions!
- motohagiography 5y agoSuper cool of you to respond. You're solving one of the most interesting problems in security. I worked on a concept for modelling an SPV for an event driven ILS for cyber policies many years ago, and the barrier was the bond modelling people wanted a standardized risk model signed off by a university, which to me seemed like /dev/null for risk, and seemed to miss the point. I'm just excitable about that topic, it's probably not a useful public discussion, I'll certainly keep an eye to what you're doing for my institutional clients. Rooting for you.
- baxtr 5y agoI work for a large insurer underwriting cyber. For large companies the answer is a clear yes. At least we do this. It is not very complicated process, but depending on the IT/OT complexity it might take 1-2 weeks to gather the data since it usually requires the input from many stakeholders within the company. What I'm always amazed by: companies think protection only when thinking about cyber. But that's not how an insurance thinks about. You have got to take into account what is at stake, too.
- bladegash 5y agoI work within this space in terms of performing the actual assessments / audits. It varies based on underwriting insurance provider. Some require compliance with certain standards (e.g., NIST CSF, PCI/DSS, etc.) and evidence of said implementation of security controls (e.g., via an independent third-party assessment). I've even begun seeing a trend towards tying coverage to use of continuous monitoring platforms, which I see becoming the norm within the next couple of years. Basically, not only will they want to see where you are at before the policy is underwritten, they also will expect you maintain compliance and they can verify that compliance via CM. In my opinion, use of CM would actually benefit the customer more than anything, as these policies are written in such a way I am skeptical they'll ever pay out (e.g., 100% compliance with something like NIST CSF is a pipe dream; you will always have some level of implementation snafus and oversights/negligence).
- bhartzer 5y agoDo any of the audits ever include a risk assessment of the company's domain names and how they're being used? And how they're set up?
- bladegash 5y agoIt COULD, depending on the standard used and level of risk. If you have a product that is publicly available/accessible and the domain is not using DNSSEC or you're not using TLS/SSL to protect data in transit, you're probably going to get hit. Or another thing I would look like is the controls that are implemented with the domain registrar itself (e.g., is two factor authentication enabled, principle of least privilege implemented, etc.). Scoping your information system is one of the most important and difficult parts of cybersecurity. Many would not think that implementation of controls with their domain registrar would be in scope. But if you think of the reality, something like weak authentication in use by a domain registrar or lack of protection of data at rest/in transit is potentially just as risky any other service provider/your internal boundary. This is especially true if your product is quite literally dependent on the domain name resolving properly.
- 5y ago
- balgan 5y agoHi, person responsible for the teams that do this at Coalition! Anytime you get a quote from us, we scan all your domains, subdomains and ip addresses. We hit the main ports that might have services running we know are dangerous and your quote might come back contingent on certain actions, for example: if you have Admin panels exposed to the internet we will require that you put them behind a VPN. We give you a PDF that describes all our findings and how we did the association with your org. If you become a policyholder we offer perimeter scanning and notify you when we find weird stuff and make security experts available at no cost to help you fix things! You can read more about it here https://www.coalitioninc.com/blog/analyzing-policyholders-technologies https://www.coalitioninc.com/blog/analyzing-policyholders-te... though what we do at underwriting time has substantially evolved since. Ask me anything here or on twitter @balgan